CVE-2026-91765

Alta7.5Publicada el 25 de septiembre de 2026

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.

Puntuación CVSS7.5 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Tipo de debilidad (CWE)CWE-674

Artículos relacionados

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de datos CVE